2024-10-23 | 24015Added · Updated
Financial institutions must develop, document, and implement a written information security programme comprising administrative, technical, and physical safeguards appropriate to their size and complexity. The Board of Directors is required to approve the programme, set oversight policies, and receive annual reports on risk assessments, testing results, and security breaches. Management must establish internal controls, conduct regular independent testing, and ensure employees receive annual security training and background checks. Specific obligations include maintaining a six-year record retention period under the Proceeds of Crime Act, 2000, securing electronic data with encryption and firewalls, and enforcing contractual security measures for service providers.